+ Reply to Thread
Results 1 to 4 of 4
Like Tree5Likes
  • 3 Post By zorgion
  • 2 Post By Joefish

Thread: Unlocked Physical Memory

  1. #1
    Senior Member
    Join Date
    May 2009
    Location
    Hueco Mundo
    Posts
    618

    Unlocked Physical Memory

    Link to original post: http://www.rohitab.com/discuss/topic...ysical-memory/

    Attached Files Attached Files
    Last edited by counterstrikewi; 3 Weeks Ago at 20:13. Reason: added video and attachment
    root86, cyberboy and StaTiX like this.
    http://home.no/zorgion/bsod.jpg

  2. #2
    Senior Member
    Join Date
    Jun 2011
    Location
    EAX
    Posts
    392
    You can pull some hard shit with this , the author dosent like that though , so i guess i wont , since i kinda respect the guy

  3. #3
    Senior Member
    Join Date
    Jun 2008
    Location
    0x40000
    Posts
    1,467
    Why would malware use this? If one needs to load a driver to access kernel memory, why not do the things you want done in the kernel in the driver code? Only use (for malware) would be to dump out memory and inject a payload (but then again, if you want a kernel payload, why not compile as a driver?)

  4. #4
    Night's Watch
    Join Date
    Oct 2009
    Location
    Clng(&H1337 Xor &H11AD)
    Posts
    361
    Quote Originally Posted by SqUeEzEr View Post
    Why would malware use this? If one needs to load a driver to access kernel memory, why not do the things you want done in the kernel in the driver code? Only use (for malware) would be to dump out memory and inject a payload (but then again, if you want a kernel payload, why not compile as a driver?)
    I agree, if you're able to load a driver then why the hell would you need direct access to physical memory? You've got everything you need already.
    I suppose if the guy is just using it as a tool to sniff about, fine... but I can't think of a valid malware use for this either.

    Besides, Firewire devices have DMA, so you can plug something into the Firewire port and have it dump the entire contents of physical memory, or inject whatever you want that way.
    root86 and SqUeEzEr like this.

    Code to express, not to impress make f*in money lol learn

    http://i46.tinypic.com/kbx853.png

 

 

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Memory-Only Malware
    By vkl in forum Malware Discussion and General Help
    Replies: 5
    Last Post: 15-04-2011, 11:08
  2. How to Crash memory [Help]
    By t3rmin4t0r in forum Visual Basic Help
    Replies: 7
    Last Post: 07-01-2011, 15:09
  3. vb application memory
    By doriiann in forum Visual Basic Help
    Replies: 3
    Last Post: 19-04-2010, 16:37
  4. Memory reading
    By Jonne in forum Delphi Help
    Replies: 3
    Last Post: 15-01-2009, 20:41

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
All times are GMT +1. The time now is 11:51.
www.opensc.ws
Copyright ©2005 - 2012, OpenSC Forums



Search Engine Friendly URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.